VYPR
Critical severity9.1NVD Advisory· Published May 18, 2026· Updated May 19, 2026

CVE-2023-24215

CVE-2023-24215

Description

Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NOVUS AirGate 4G firmware v1.1.16 has an unauthenticated access control bug in /uci/get/ that leaks admin credentials.

Vulnerability

An incorrect access control vulnerability exists in the /uci/get/ endpoint of NOVUS AirGate 4G firmware version v1.1.16 [2]. The endpoint does not properly restrict access to sensitive functionality, allowing an unauthenticated attacker to retrieve administrator credentials via a crafted POST request [2]. This affects only firmware v1.1.16 of the AirGate 4G product [2].

Exploitation

An attacker can exploit this vulnerability over the network without any authentication or user interaction [2]. The attack vector is remote, and the required complexity is low [2]. The attacker crafts a POST request to the /uci/get/ endpoint, which then returns the administrator credentials to the attacker [1][2].

Impact

Successful exploitation allows an attacker to obtain the device's administrator credentials [2]. With these credentials, the attacker can gain full administrative access to the device, modify its configuration, and potentially compromise the security of the network where the device is deployed [2]. The impact includes both confidentiality and integrity loss [2].

Mitigation

As of the available references, no official patch or fixed version has been released by NOVUS [1][2]. The affected firmware version v1.1.16 remains vulnerable. Users should monitor vendor advisories for a security update and, if possible, restrict network access to the device's management interface as a workaround until a fix is available.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.